First published: Thu Sep 26 2024(Updated: )
The Jupiter X Core plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.7.5. This is due to improper authentication via the Social Login widget. This makes it possible for unauthenticated attackers to log in as the first user to have logged in with a social media account, including administrator accounts. Attackers can exploit the vulnerability even if the Social Login element has been disabled, as long as it was previously enabled and used. The vulnerability was partially patched in version 4.7.5, and fully patched in version 4.7.8.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jupiter X Core | <4.7.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-7781 has a critical severity rating due to the risk of authentication bypass.
To fix CVE-2024-7781, upgrade the Jupiter X Core plugin to version 4.7.6 or later.
CVE-2024-7781 affects all versions of the Jupiter X Core plugin for WordPress up to and including 4.7.5.
CVE-2024-7781 can be exploited by unauthenticated attackers due to improper authentication mechanisms.
The vulnerability in CVE-2024-7781 is caused by improper authentication via the Social Login widget.